View Single Post
Old 13th November 2005, 13:05
Ovidiu Ovidiu is offline
Senior Member
Join Date: Sep 2005
Posts: 1,269
Thanks: 84
Thanked 25 Times in 21 Posts
Default question regarding configuration of logcheck

hi guys,

anyone using logcheck?
If yes did you change the ignore files? I am using it in server mode or server level but it still keeps showing me some stupid logs which I want to get rid of: one example would be that it does not filter lines like this:
Nov 12 18:04:20 h5810 proftpd: (pam_unix) session opened for user web18_admin by
also in /etc/logcheck/ignore.d.server/proftpd there is this line:
^\w{3} [ :0-9]{11} [._[:alnum:]-]+ proftpd: \(pam_unix\) session (opened|closed) for user [\._[:alnum:]-]+( by \(uid=[0-9]+\))$
a line that I did not insert but was there from the start.

logcheck is set up to be in server mode
Reply With Quote
Sponsored Links